mirror of
https://github.com/warmbly/warmbly.git
synced 2026-10-03 16:02:02 +00:00
20 lines
1.2 KiB
Plaintext
20 lines
1.2 KiB
Plaintext
# Security response headers for the dashboard shell and its assets.
|
|
#
|
|
# This file is included once per location rather than set once at the server
|
|
# level, because nginx only inherits add_header from an outer block when the
|
|
# inner block declares none of its own. Every location here sets Cache-Control,
|
|
# so a server-level declaration would be silently dropped in exactly the places
|
|
# that serve the app.
|
|
#
|
|
# No script-src or connect-src: the API origin, the analytics host and the
|
|
# billing host are runtime configuration (config.js is rewritten by the
|
|
# container entrypoint), so an allowlist compiled into the image would break a
|
|
# self-host that points the dashboard somewhere else. What is pinned here is
|
|
# everything that does not depend on that configuration.
|
|
add_header X-Content-Type-Options "nosniff" always;
|
|
add_header X-Frame-Options "DENY" always;
|
|
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
|
|
add_header Permissions-Policy "camera=(), microphone=(), geolocation=(), interest-cohort=()" always;
|
|
add_header Content-Security-Policy "frame-ancestors 'none'; object-src 'none'; base-uri 'none'; form-action 'self'" always;
|
|
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
|